Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY33 SECURITY RECORDS

strukturag

libheif

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2026-84450 18 Sep 2026 libheif: >= 1.19.0, < 1.23.3 1.23.3. Update reference ↗
CVE-2026-84449 18 Sep 2026 libheif: < 1.19.6 1.19.6. Update reference ↗
CVE-2026-84451 18 Sep 2026 libheif: >= 1.19.0, < 1.23.3 1.23.3. Update reference ↗
CVE-2026-84447 18 Sep 2026 libheif: < 1.23.2 No fixed version is explicitly recorded in the structured CVE data. Update reference ↗
CVE-2026-84384 18 Sep 2026 libheif: >= 1.19.0, < 1.23.2 1.23.2. Update reference ↗
CVE-2026-84444 18 Sep 2026 libheif: < 1.23.2 1.23.2. Update reference ↗
CVE-2026-84383 18 Sep 2026 libheif: >= 1.22.0, < 1.23.2 1.23.2. Update reference ↗
CVE-2026-84446 18 Sep 2026 libheif: < 1.23.2 1.23.2. Update reference ↗
CVE-2026-84448 18 Sep 2026 libheif: < 1.23.2 1.23.2. Update reference ↗
CVE-2026-62377 18 Aug 2026 < 1.23.1 1.23.1. Update reference ↗
CVE-2026-62291 18 Aug 2026 < 1.23.1 1.23.1. Update reference ↗
CVE-2026-62292 18 Aug 2026 >= 1.19.0, < 1.23.1 1.23.1. Update reference ↗
CVE-2026-62289 18 Aug 2026 < 1.23.1 1.23.1. Update reference ↗
CVE-2026-50142 18 Aug 2026 >= 1.19.0, < 1.23.0 1.23.0. Update reference ↗
CVE-2026-48029 22 Jul 2026 >= 1.19.0, < 1.22.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-47709 21 Jul 2026 < 1.22.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-47254 21 Jul 2026 < 1.22.0 No fixed version is explicitly recorded in the structured CVE data. Update reference ↗
CVE-2026-47251 21 Jul 2026 < 1.22.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-47247 21 Jul 2026 < 1.22.0 No fixed version is explicitly recorded in the structured CVE data. Update reference ↗
CVE-2026-47178 21 Jul 2026 >= 1.19.0, < 1.22.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-47714 21 Jul 2026 < 1.22.0 No fixed version is explicitly recorded in the structured CVE data. Update reference ↗
CVE-2026-49271 19 Jun 2026 < 1.22.1 No fixed version is explicitly recorded in the structured CVE data. Update reference ↗
CVE-2026-41071 22 May 2026 < 1.22.0 1.22.0. Update reference ↗
CVE-2026-41069 22 May 2026 < 1.22.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-32882 19 May 2026 < 1.22.0 1.22.0. Update reference ↗
CVE-2026-32741 19 May 2026 < 1.22.0 1.22.0. Update reference ↗
CVE-2026-32814 19 May 2026 < 1.22.0 1.22.0. Update reference ↗
CVE-2026-32740 19 May 2026 < 1.22.0 1.22.0. Update reference ↗
CVE-2026-32739 19 May 2026 < 1.22.0 1.22.0. Update reference ↗
CVE-2026-32738 19 May 2026 < 1.22.0 1.22.0. Update reference ↗
CVE-2026-3950 11 Mar 2026 1.21.0; 1.21.1; 1.21.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-3949 11 Mar 2026 1.21.0; 1.21.1; 1.21.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-68431 29 Dec 2025 < 1.21.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.